Halborn · Vulnerability Disclosure

Halborn Vulnerability Disclosure

Vulnerability disclosure

Halborn publishes a vulnerability disclosure policy for reporting security issues.

CompanySecurityCybersecurityBlockchainSmart ContractsSecurity AuditingPenetration TestingWeb3Vulnerability DisclosureComplianceFinancial ServicesProfessional Services
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

halborn-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-22'
method: searched
source: https://www.halborn.com/disclosures/disclosure-policy
docs: https://www.halborn.com/disclosures/disclosure-policy
program:
  published: true
  name: Halborn Vulnerability Disclosure Policy
  url: https://www.halborn.com/disclosures/disclosure-policy
  http_status: 200
  contact_email: disclosures@halborn.com
  security_txt: false
  security_txt_note: >-
    /.well-known/security.txt returns 404 on www.halborn.com and one.halborn.com; the policy is
    published as an HTML page only, so it is not machine-discoverable per RFC 9116.
  bug_bounty: false
  bug_bounty_platform: null
  rewards: >-
    Discretionary. For issues affecting non-Halborn products Halborn credits the reporter on its
    public disclosures page; for issues affecting Halborn a reward may be issued at the discretion
    of Halborn senior leadership, based primarily on severity.
scope:
  covers:
  - Vulnerabilities discovered by Halborn that affect other entities
  - Vulnerabilities reported to Halborn that affect other entities
  - Vulnerabilities reported to Halborn that affect Halborn
  cve_numbering_authority: true
  cve_assignment_scope: >-
    All blockchain and Web3 products relying on smart contracts written in Rust, Go and Solidity,
    plus blockchain-associated Web2 and Web3 infrastructure not covered by another CNA.
severity_scoring:
- scheme: CVSS
  version: '3.1'
  use: Scoring of vulnerabilities handled under this policy.
  evidence: https://www.halborn.com/disclosures/disclosure-policy
- scheme: BVSS
  version: null
  use: >-
    Halborn's own Blockchain Vulnerability Scoring System, published as a proprietary framework for
    scoring smart contract risk.
  evidence: https://www.halborn.com/bvss
service_levels:
- event: acknowledgement of a valid submission
  window: 24 hours
- event: detailed response with perceived severity and next steps
  window: 72 hours
- event: reminder to a non-responding affected vendor
  window: 7 days after initial contact
- event: Halborn may publicly disclose if vendor does not respond or refuses to acknowledge
  window: 14 days from initial contact
- event: vendor patch window before disclosure
  window: 90 days (adjustable at Halborn's discretion based on severity and exploitability)
- event: maximum coordination period before disclosure regardless of fix
  window: 6 months
publication:
  disclosures_index: https://www.halborn.com/disclosures
  disclosures_feed: https://www.halborn.com/disclosures/feed.xml
  note: >-
    Halborn states that only advisories present in the security advisory are official documents.
    All CVEs assigned by Halborn and its disclosures are published on the disclosures page, which
    also carries an RSS feed.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/halborn-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.